Privacy Policy
Last updated: 23 August 2026 · Additional clauses: 6 October 2026
Kiyo respects your privacy. This policy explains how we collect, use, and protect personal information when you use our platform or make a booking through a property that uses our service.
1. Information We Collect
We collect: (a) Account information — name, email, business details provided during registration; (b) Booking information — guest name, contact details, and stay information; (c) Usage data — pages visited, features used, device and browser information; (d) Payment information — processed securely by our payment partners; we do not store card numbers. Depending on the services used, this also includes operational guest correspondence, support requests, account permissions, connection identifiers and the bank, tax and identity-verification information needed to administer the operator account and payouts. Provide only information necessary for the service and do not put full payment-card numbers, security codes or unrelated sensitive personal information into messages, uploads or free-text fields.
2. How We Use Your Information
We use your information to: provide and improve the platform; process bookings and payments; send booking confirmations and operational notifications; comply with legal obligations under Indonesian Personal Data Protection Law (UU PDP) and GDPR where applicable; and prevent fraud and maintain platform security. Kiyo determines the purposes of processing its own customer-account, billing, support, fraud-prevention and security information. When a property operator uses Kiyo to manage guest or staff information on that operator's instructions, the operator is the controller and Kiyo processes the information on its behalf. The operator must establish a lawful basis and give the individuals the privacy information required for its accommodation and communications. Depending on the activity and applicable law, processing relies on performance of a contract, legal obligations, permitted legitimate interests or consent where required. Reading or accepting this policy is not a substitute for separate consent where the law requires it.
3. Data Sharing
We do not sell your personal data. We share data only: (a) with property operators to fulfil your booking; (b) with payment providers to process transactions; (c) with infrastructure and analytics providers under data processing agreements; (d) when required by law or valid court order. Configured channel-distribution, guest-communication and support services may receive the information necessary to deliver the function selected by the operator. Access by Kiyo personnel and service providers is limited to the relevant service, support, security or legal purpose, with confidentiality and data-protection obligations where they act on our behalf. Connected accommodation, travel and payment providers may act as independent controllers for their own activities; their notices apply to those activities. Contact us for information about the recipients relevant to your account. Disconnecting a service stops future exchanges through that connection but does not automatically erase records already lawfully received by it.
4. International Data Transfers
Our infrastructure is hosted on servers that may be located outside Indonesia. Where personal data is transferred internationally, we ensure appropriate safeguards are in place, including standard contractual clauses where required under applicable law. For transfers subject to Indonesian law, we apply the required assessment of equivalent or higher protection, adequate binding safeguards or, where the statutory conditions require it, the individual's consent. EU or UK transfer instruments apply where those laws govern the transfer. An overseas server location does not remove Kiyo's or the operator's applicable data-protection obligations.
5. Data Security
We implement industry-standard security measures including encryption at rest and in transit, access controls, and regular security reviews. No system is completely secure — if you believe your account has been compromised, contact us immediately. If a personal-data incident affects information we process, we investigate and take appropriate mitigation steps, notify the relevant operator when processing on its behalf, and make any notifications required by applicable law. Statutory notification deadlines apply. The operator and its authorised users must protect access credentials, restrict account permissions and report suspected compromise promptly.
6. Your Rights
Under applicable law, you have the right to: access your personal data; correct inaccurate data; request deletion (where no legal retention obligation applies); object to certain processing; and withdraw consent. Submit requests to our support team. We respond within 30 days. Where applicable law requires a shorter deadline, that deadline takes precedence over the general response periods stated in this policy. We may request proportionate identity or authority verification and explain any lawful restriction or retention requirement. For guest information controlled by a property, contact the operator as well; we assist it with requests concerning information processed on its behalf. Withdrawal of consent does not undo earlier lawful processing or prevent retention required by law.
7. Cookies
We use cookies and similar technologies for security, functionality, performance analytics, session recording on designated Kiyo website and product pages, social-channel measurement, and advertising measurement when a provider is configured. Optional categories start enabled. You can review or change them at any time in the Cookie Center; Strictly Necessary cookies cannot be disabled.
When Performance or Targeting is enabled, Google Analytics and Google Tag Manager may collect pages visited, device or browser details, referral or campaign context, and approved conversion actions. We do not send passwords, payment details, or form-field values. Google explains how it collects and processes this information: How Google uses information from sites or apps that use its services
When Performance is enabled, Kiyo sends a limited set of anonymous page, call-to-action, engagement, and confirmed-form events to PostHog. Session replay is restricted to designated Kiyo account and PMS routes with input masking; it is off on corporate marketing, property, and booking pages. When Targeting is enabled, configured advertising providers such as Meta Pixel may receive page and marketing-conversion events. Vercel independently creates limited operational request logs needed to deliver, secure, and troubleshoot the site; those logs are not controlled by Cookie Center choices.
8. Data Retention
We retain account data for as long as your account is active, plus 12 months. Booking records are retained for 5 years to comply with Indonesian financial regulations. Anonymised analytics data may be retained indefinitely. Account reactivation and product-access periods are separate from record-retention periods: ending access or a 30-day reactivation window does not automatically erase records retained under this section. The periods above are subject to applicable statutory requirements, including any mandatory shorter or longer period. We retain only the information needed for the relevant legal, accounting, fraud-prevention or dispute purpose, restrict its use accordingly, and delete or anonymise it when that purpose ends. Backup copies are protected from ordinary use and removed through the applicable backup lifecycle. A deletion request may therefore remove active-service information while legally required records remain restricted.
9. Children
Kiyo is not directed at children under 18. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected information from a minor, contact us and we will delete it promptly.
10. Changes to This Policy
We may update this policy periodically. Material changes will be communicated by email and in-platform notification at least 14 days before taking effect. Continued use after that date constitutes acceptance of the updated policy. A policy update does not create a new lawful basis for processing or replace consent required by law. Material changes remain subject to the notice described above and to applicable rights to object, withdraw consent or request deletion. The English and Indonesian versions describe the same practices; mandatory law governs if an interpretation would limit an individual's statutory rights.
11. Contact & Data Protection
For privacy enquiries, data access requests, or complaints, contact our Data Protection team. We aim to respond within 5 business days. You also have the right to lodge a complaint with the relevant data protection authority in your jurisdiction.
12. Where Your Information Comes From
We receive information directly when you create an account, complete a booking, submit a form, contact support or enter information into a Kiyo feature. We also receive information from the property operator and its authorised users, and from the booking, payment and communication services connected to the relevant account. Those sources may provide booking changes, payment or refund status, guest correspondence and the identifiers needed to match a record to the correct property. Technical information may be generated automatically when a browser or service interacts with the platform. If an operator supplies information about a guest, employee or other person, that operator must have a lawful basis, provide the required privacy information and limit the information to what the selected service needs. The source of information does not remove the individual's applicable privacy rights. If you want to know how information associated with you entered Kiyo, contact us and identify the relevant property or account.
13. Property Administrators and Authorised Users
A property operator determines which of its owners, administrators, employees and agents may use its Kiyo account. Depending on their assigned permissions, these users may view or manage guest records, reservations, communications, operational information and reports. An administrator may also manage staff access and connected services. Information that a user enters into a property workspace can therefore be available to other authorised users of that workspace; it is not necessarily a private communication with Kiyo. Operators must assign permissions appropriately, keep authorisation current and remove access when a person no longer needs it. Users must protect their credentials and promptly report suspected misuse. Requests concerning information held for a property may need to be handled with that operator, including after a staff member leaves. These responsibilities do not release Kiyo from its own applicable security or data-protection duties.
14. Connected Booking Channels and Messaging
Channel distribution and guest communication require information to move between Kiyo, the property and the services the operator enables. Depending on the connection, this can include property details, availability, rates, restrictions, booking identifiers, guest contact details, stay information, messages and booking changes. An operator's configuration and authorised actions instruct the exchanges necessary for those functions. Messages and attachments should contain only information appropriate for the booking or other lawful purpose. A connected travel, accommodation, messaging or payment service may keep its own records and determine its own processing purposes. Its privacy notice governs those independent activities. Kiyo's policy does not give an operator permission to send unsolicited guest marketing or to disclose unrelated information. Revoking a connection or token stops future exchanges through that connection, subject to any operational processing needed to complete the revocation; it does not automatically withdraw information already lawfully received by the other service.
15. Payment Verification and Transaction Records
Payment services may require verification of an operator's business, tax information, identity and nominated bank account. Kiyo processes the verification and transaction information needed to administer collection, payouts, fees, refunds, reversals and disputes. Records can include payment references, amounts, currencies, transaction status, bank destination information, verification status and supporting correspondence. The payment provider may request additional information under its own regulatory and verification requirements. An individual's financial privacy rights remain applicable even where records must be kept for accounting, fraud prevention or a dispute. Do not send full card numbers, card security codes, banking passwords or one-time authentication codes through general support, guest messages or other free-text fields. Use the designated payment or verification flow. The Privacy Policy explains information handling; the Terms of Service and applicable provider terms govern payment authority, fees, refunds and payout obligations.
16. Support Access, Diagnostics and Audit Records
When you ask for support, Kiyo may process your correspondence, relevant screenshots or attachments, and the account or operational records needed to investigate the request. Relevant personnel may access the affected account information to provide support, maintain the service, investigate security issues or meet legal obligations. Access is limited by the purpose of the work and applicable confidentiality and authorisation requirements. Please remove unrelated guest information, passwords and financial secrets before sending a support attachment. Operational and audit records may include account or property identifiers, actions, timestamps, request status, IP addresses, browser information and error details. These records support troubleshooting, accountability, fraud detection and security investigations. An account identifier or a partially masked record can still be personal data when it can be linked to a person. Diagnostic records are therefore subject to the relevant protections and retention requirements; they are not treated as public information merely because they are technical records. References above to a named hosting provider describe that provider's role when it is in use. Infrastructure can change, and current delivery, security and diagnostic logs are handled by the providers that actually operate the relevant component. Contact us for current recipient information; a historical provider reference does not expand that provider's access to your information.
17. Sensitive Information and Information About Other People
Only submit sensitive information when it is necessary for a supported service and there is a lawful basis for that processing. Identity documents, personal financial information, health information, biometric information, children's information and other specially protected categories may require additional safeguards or consent under applicable law. Do not place unrelated sensitive details in reservation notes, chat messages, support requests or uploads. A person's permission to make a booking does not automatically authorise every further use of their information. Section 9's age restriction concerns people using Kiyo's platform accounts. As a limited exception to its general statement about children's information, an adult operator may instruct necessary processing of a lawful family-booking record if it meets applicable parent or guardian consent and other requirements. This does not make Kiyo a service directed at children. If information about a child or other sensitive information has been submitted without the required authority, contact the operator and Kiyo promptly so the information can be restricted, corrected or removed as appropriate. Mandatory retention and privacy duties continue to apply.
18. Marketing Preferences and Essential Communications
Kiyo may communicate with its business contacts about the service and, where permitted by applicable law, relevant product news or offers. You can ask us to stop promotional communications through the available unsubscribe mechanism or by contacting our support address. When consent is required for marketing, general acceptance of this policy does not replace that consent. An operator that markets to its guests is responsible for the required lawful basis, notices and marketing preferences for those communications. Booking confirmations, payment and refund updates, security alerts, essential account notices and responses to requests serve operational or legal purposes. Opting out of promotional messages does not necessarily stop those essential communications while the relevant service, booking, account or legal obligation remains active. We do not treat a guest's booking information as unrestricted permission to send marketing. Tracking and measurement preferences remain subject to the Cookies section and any separate consent required by applicable law.
19. AI Assisted Features and Automated Processing
Where an operator uses AI assisted features, the information needed for the selected task may include its instructions, relevant conversation content and operational context. External AI services may process the information required for that function. Privacy controls can mask or remove sensitive values, but masking individual fields does not guarantee that the remaining context is anonymous. Do not submit payment credentials, unrelated identity documents or unnecessary sensitive information in an AI request. Such processing remains subject to the relevant data roles, lawful basis, service-provider safeguards and international-transfer requirements described in this policy. AI generated content may be inaccurate and should be reviewed before it is used in guest communications or business actions. Ordinary configured rules may also check availability, calculate amounts, send notifications or update transaction status. If automated processing affects you and applicable law gives you a right to an explanation, challenge or human review, contact the relevant property operator or Kiyo. This policy does not grant permission for unrelated publication or model-training use of identifiable guest information; such uses require their own lawful basis and any required notice or consent.
20. Aggregated and De-identified Information
Kiyo may use usage patterns and appropriately aggregated or de-identified information to understand service performance, diagnose problems and improve the platform. The protections in this policy continue to apply whenever information can identify a person, directly or by combination with other available information. Removing a name, replacing it with an identifier or grouping a small number of records does not by itself make information anonymous. Information described as anonymised must no longer reasonably identify an individual. The indefinite retention described for anonymised analytics does not apply to identifiable guest records merely because they appear in an analytics system. Where measurement uses cookies, device identifiers or other personal data, the applicable privacy, tracking and consent requirements still apply. We do not treat de-identification as permission to expose confidential property records or personal information publicly.
21. Account Closure, Data Export and Backups
A property administrator should arrange any necessary export and continued handling of bookings before closing an account or disconnecting an important service. Guests and staff may request access to information concerning them through the appropriate controller. Account closure, cancellation of a subscription and a request to erase personal data are different actions: closing product access does not itself cancel a guest's stay, settle a refund or remove every record that another controller lawfully holds. We distinguish active operational information from records retained for legal, accounting, security or dispute purposes. Retained records remain subject to access restrictions and purpose limitations. Backup copies may persist within the applicable backup lifecycle, and restoring a backup must not turn a completed deletion or restriction request into unrestricted new processing. Requests for export, return, restriction or deletion are handled under the applicable rights and statutory deadlines; this section does not create a new blanket retention period or override the limits already described in this policy.
22. Business Transfers and Legal Requests
In addition to the disclosures described in Section 3, relevant account and service records may need to be transferred as part of a lawful merger, acquisition, reorganisation or transfer of the business operating Kiyo. Any due-diligence disclosure must be proportionate, subject to appropriate confidentiality and data-protection safeguards, and limited to the purpose of that transaction. A change of ownership does not remove applicable privacy obligations or automatically permit unrelated use of guest information. We provide notice or obtain additional consent where applicable law requires it. We may also retain or disclose relevant information to respond to lawful authorities, protect the service against fraud or misuse, or establish, exercise or defend legal claims where the law permits or requires it. Such requests are assessed for authority and scope; the disclosure should be limited to the information relevant to the lawful purpose. An operator cannot use this policy to compel disclosure of another property's information or override another person's statutory rights.
23. Privacy Requests, Complaints and Mandatory Rights
Send privacy requests and complaints to the contact address in Section 11. Tell us the relevant property or account, the type of information involved and the action you are requesting. Provide enough information for us to locate the records and verify your identity or authority, without sending unnecessary identity documents or secrets. An authorised representative may need to establish permission to act. If Kiyo processes the information on a property's behalf, we coordinate with that operator rather than treating the guest's records as Kiyo's own customer-account information. We explain any lawful reason why a request cannot be completed in full, including mandatory retention, protection of another person's rights or lack of authority over a third party's records. The statutory deadlines and mandatory rights take precedence over general support targets. You may escalate concerns through the relevant data-protection authority or other legal route available in your jurisdiction. Neither acceptance of the service Terms nor this Privacy Policy waives rights that cannot lawfully be waived, and the policy does not exclude Kiyo's own mandatory responsibilities.
For privacy enquiries, data access requests, or complaints, contact our Data Protection team. We aim to respond within 5 business days. You also have the right to lodge a complaint with the relevant data protection authority in your jurisdiction.
Email our privacy team → hello@kiyoHQ.com